Impact
Adobe Commerce versions 2.4.9-alpha3 through 2.4.4-p16 contain a stored XSS vulnerability (CWE‑79). A high‑privileged attacker who can inject data into vulnerable form fields can execute arbitrary scripts in the victim’s browser when the victim visits the affected page. This can lead to session hijacking, credential theft, or the execution of further malicious code, reducing the confidentiality and integrity of the application and potentially the underlying system.
Affected Systems
The vulnerability affects Adobe Commerce (and associated Magento open‑source) installations with the following versions: 2.4.9‑alpha3, 2.4.8‑p3, 2.4.7‑p8, 2.4.6‑p13, 2.4.5‑p15, 2.4.4‑p16 and all earlier releases. All these releases are listed as affected in the Adobe security advisory.
Risk and Exploitability
The CVSS score is 4.8, indicating a moderate severity. EPSS is below 1%, showing a low probability of exploitation in the near term. The attack requires high‑privilege compromise of the site and user interaction, meaning it is not an externally exploitable remote vulnerability. It is not currently listed in the CISA KEV catalog, which suggests no widespread public exploitation has been observed yet.
OpenCVE Enrichment